Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
Products / Services
1
1
1
MITRE Techniques
1
1
1
CVEs
68
68
58
56
50
IDS Classtypes
1
IDS Protocols
1
Detects incoming HTTP requests to a FortiSandbox device that contain suspicious command injection patterns. The rule monitors both the URI and the request body for shell metacharacters such as ';', '|', '`', '$(', or '&&', followed by common binary execution commands (e.g., cat, wget, curl, bash, rm). This behavior is indicative of an exploit attempt targeting CVE-2026-39808.
